Manager - Information Security (Compliance)
At Basware , we deliver mission-critical cloud solutions that empower organizations to unlock their full potential. Our products are designed to bring clear and compelling value to our customers, and we’re looking for talented and forward-thinking professionals who can help us shape the future of our technology. We are seeking a Manager - Information Security (Compliance) , an experienced security compliance specialist who thrives at the intersection of governance, risk management, and stakeholder engagement. In this role, you will help ensure that Basware maintains a robust and effective security compliance program while supporting customers, auditors, suppliers, and internal teams with practical, risk-based guidance. The Information Security Compliance team supports the organisation in maintaining an effective, risk-based information security management system. The Manager - Information Security (Compliance) will coordinate key compliance, assurance and risk management activities, working closely with business and solution owners to strengthen security governance, support audit readiness and drive continual improvement. Customer and stakeholder assurance Manage the Security Advisory process, including completion of due diligence questionnaires, requests for information and general information security queries from customers, prospects, partners and customer-facing colleagues. Provide practical information security and compliance advice to colleagues, projects, solution owners and business stakeholders, escalating material risks where appropriate. Risk, supplier assurance and business continuity Conduct and support third-party information security risk assessments and periodic supplier reviews, documenting findings, risks, recommendations and follow-up actions. Maintain the information security risk register, coordinate periodic risk reviews, monitor treatment actions and support the CISO and risk owners in recording clear, proportionate and current risk information. Support business continuity activities, including assisting business owners with the completion and review of Business Impact Analyses and tracking related actions. Audit and corrective action management Plan, coordinate and perform internal information security audits, record audit evidence and findings, and monitor agreed corrective actions and opportunities for improvement. Support external audits and assurance activities by coordinating evidence, engaging relevant control owners and responding to auditor queries. Agree appropriate corrective actions and implementation dates with control owners, and proactively support delivery to ensure agreed timelines are achieved. Compliance initiatives and awareness Develop appropriate security training and communications that promote a positive information security culture. Manage assigned compliance initiatives and improvement activities, maintaining clear plans, priorities, dependencies and stakeholder communications. Experience and technical knowledge Minimum of two years’ experience working in information security or security compliance. Strong knowledge of recognised information security control frameworks and assurance standards, such as ISO/IEC 27002, PCI DSS, the NIST Cybersecurity Framework and ISAE standards. Practical experience of information security risk management, including risk identification, assessment, treatment, monitoring and reporting. Experience supporting internal or external audits, evidence collection, control testing and remediation tracking. Communication and stakeholder engagement Strong written and verbal communication skills, with the ability to explain security and compliance requirements clearly to technical and non-technical audiences. Strong influencing and stakeholder management skills, with the confidence to provide constructive challenge and secure commitment to agreed actions. Planning, organisation and working style Effective project management and organisational skills, with the ability to manage competing priorities, actions and stakeholders. A structured, detail-focused and improvement-oriented approach, with sound judgement and the ability to work both independently and collaboratively. Professional qualifications Relevant professional certification or training in information security, audit, risk or compliance is desirable. Experience with AI tools, frameworks or applications is considered a strong asset. We highly value candidates who demonstrate curiosity, a proactive mindset and a willingness to explore and incorporate AI-driven technologies into their work. We encourage growth in this area and provide opportunities for experimentation and learning. Why Basware? We’re a purpose-driven company with a global footprint and a collaborative culture. At Basware, you’ll work with passionate professionals, cutting-edge technology, and a shared commitment to innovation and excellence. Ready to make an impact? If you're excited by the challenge, apply now and help shape the future of Basware. Please submit your resume and cover letter by clicking the ‘ I’m interested ’ link. Our recruitment process will include pre-employment actions such as enhanced background screening and reference check. Basware. Now it all just happens.
Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.
Visa jobbet och ansökUrsprunglig annons: emp.jobylon.com